Recovery Lab undeletes files, carves data off formatted or wiped drives, and repairs broken or truncated photos, audio and video — into a hashed, signed bundle you can trust.
Self-hosted, read-only on your source media, nothing uploaded. The recovery engine that powers Crucible's forensics — available on its own.
A deleted file, a quick-formatted SD card, a phone backup that won't open, a video that cuts off halfway — most "lost" data isn't actually gone. Recovery Lab is a self-hosted workstation that recovers it three ways — filesystem-aware undelete, signature carving, and media repair — and writes the results to a SHA-256-hashed, signed bundle. Built on the same deterministic engine that backs Crucible's court work, so it's clean enough for a case and simple enough for a Saturday rescue.
Point it at a drive, a partition, or a disk image — and pick the right tool, or run them all.
Filesystem-aware recovery (NTFS, ext, FAT, HFS+) with the Sleuth Kit and ntfsundelete — brings back files the filesystem still tracks, with their names and a deleted-inode listing intact.
Reconstructs files by signature when there's no filesystem left — photos, PDFs, Office docs, video, archives — recovered from a quick-formatted or corrupted volume's unallocated space.
Remuxes and rebuilds broken or truncated audio and video — recovers the playable portion of a partial clip, and rebuilds truncated MP4/MOV from a healthy reference file from the same camera.
A complete salvage pipeline — image, recover, repair, export.
Built-in ddrescue clones a dying or flaky disk to an image — with a map file — so every recovery step runs on a safe copy and never stresses the failing hardware again.
Sleuth Kit tsk_recover + ntfsundelete recover deleted files across NTFS, ext, FAT and HFS+ — with original names and a full deleted-inode listing for the report.
foremost, scalpel and photorec reconstruct files from raw unallocated space by header/footer — finding what undelete can't, even after a format.
ffmpeg salvages playable streams from partial files; untrunc rebuilds truncated video using a healthy reference from the same device. Turns carved fragments back into playable clips.
Every job's results are catalogued with per-file SHA-256 and an Ed25519 signature over the bundle — re-verifiable later, court-ready, and ingestible straight into a case.
Recovery Lab never writes to the media it reads. Mount read-only or work from an image — your evidence (or your only copy) is never altered.
Damaged or deleted, on a drive or an image — to a clean, hashed bundle.
Point ddrescue at a dying drive to clone it to a safe image first. Healthy media? Skip straight to recovery — read-only.
Run filesystem-aware undelete to bring back tracked-but-deleted files with their names — across NTFS, ext, FAT and HFS+.
Signature-carve the unallocated space for everything the filesystem no longer tracks — formatted, wiped, or orphaned files, by type.
Remux partial clips and rebuild truncated video so the carved fragments actually play — keep a small reference-clip library per camera for the best results.
Everything lands in a hashed, signed bundle — open the files directly, or ingest the whole thing into a Crucible case timeline.
Recovery-shop power, on your own terms.
Runs on your hardware — your data never leaves the building, and there's no per-job cloud fee or a stranger handling your drive.
Deterministic open-source engines (Sleuth Kit, foremost, photorec), read-only sourcing, hashed + signed output — defensible if it ever matters.
Most tools stop at carving and hand you broken fragments. Recovery Lab repairs the media too, so partial clips actually play.
No arcane command lines — point at a drive or image, pick a mode, get a bundle. The same polished UI as the rest of the suite.
NTFS, ext, FAT, HFS+, raw images, SD cards, USB drives, disk images — Windows, Mac and Linux media all welcome.
Built and supported by Richey Business — you can actually reach us.
Recovery Lab is included in Crucible — and the recovered files drop straight into a case.
Recovery Lab ships as the Recovery & Repair capability inside Crucible's Extraction Studio — every recovered or repaired file flows into the same UTC-normalized, chain-of-custody case timeline, alongside phone extractions and OSINT. Need recovery without the full forensic platform? Recovery Lab stands alone too. Explore the full Crucible suite →
The same clean, themeable interface as the rest of the suite.




Recovery shops, IT teams, investigators, or anyone who just lost something they can't lose — book a walkthrough, or talk to us about a private, self-hosted deployment.